Enables or disables Online Certificate Status Protocol (OCSP) nonce for RADIUS TLS servers.
tls | Specifies Transport Layer Security (TLS). |
ocsp | Specifies the OCSP attribute. |
nonce | Specifies to cryptographically bind an OCSP request and an OCSP response with the extension id-pkix-ocsp-nonce to prevent replay attacks. |
on | Specifies to include the id-pkix-ocsp-nonce extension in the OCSP request and response. |
off | Specifies to exclude the extension (default). |
Off.
The following example configures nonce:
# configure radius tls ocsp nonce on
This command was first available in ExtremeXOS 32.2.
This command is available on ExtremeSwitching 5320, 5420, 5520, and 5720 series switches.